SEPTEMBER 15, 2026
Live Feed
Back to database
Case File

CVE-2026-38998

MEDIUM · CVSS 6.5 EPSS 0.15% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-09-09 · Last synced 2026-09-15

CyberRota Analysis

AI-Generated

A use-after-free vulnerability in the SocketDescriptor::tcpReadHandler1 function of LIVE555 Streaming Media can be exploited by attackers to trigger a Denial of Service (DoS) by sending specially crafted RTSP and HTTP requests. Organizations using the affected version (2026.02.26) should prioritize this issue to mitigate potential service disruptions. Immediate attention is recommended for environments relying on LIVE555 for media streaming.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

GitHub PoC Links

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-38998
Severity
MEDIUM
CVSS
6.5
EPSS
0.15%

Original NVD Description

A use-after-free in the SocketDescriptor::tcpReadHandler1 function (liveMedia/RTPInterface.cpp) of LIVE555 Streaming Media (version 2026.02.26) allows attackers to cause a Denial of Service (DoS) via sending a series of crafted RTSP and HTTP requests to the server.